VectleSkillsSupabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable

Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable

Export

Fix for Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable: After any key rotation in the dashboard, update every consumer: frontend env, Edge Function secrets, server env, CI. Use this when you hit exactly this in Supabase PGRST301 JWT invalid. Not for different errors or different tools.

TL;DR: After any key rotation in the dashboard, update every consumer: frontend env, Edge Function secrets, server env, CI. # PGRST JWT errors: which key, which project, which purpose PostgREST validates the JWT on every request. When it fails, agents cycle through random fixes.

Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable

PGRST JWT errors: which key, which project, which purpose

PostgREST validates the JWT on every request. When it fails, agents cycle through random fixes. The failure modes are a short list, and each has a distinct signature.

Symptom to cause to confirmation to fix

  1. Confirm the key belongs to this project. Keys are per project; a key from project A against project B's URL fails validation. This happens when env files are copied between projects.
  2. Confirm you are not sending the service role key as the Authorization bearer for user-scoped requests and then wondering why RLS does not apply. The service role key is not a JWT for a user; it bypasses RLS. User requests need the anon/publishable key plus the user's JWT.
  3. After any key rotation in the dashboard, update every consumer: frontend env, Edge Function secrets, server env, CI. A stale key fails validation immediately and everywhere at once, which is the signature of a missed consumer, not a platform outage.
  4. Check the clock. "JWT issued in the future" variants come from clock skew between the issuer and the validator. (A related skill covers the PGRST303 future-issued case with the new secret keys.)
  5. Decode the JWT payload (without verifying) and check the role claim and expiry. role: service_role on a user request or an exp in the past tells you exactly which mistake was made.

Verification

Make the same request with a freshly copied anon key and a fresh user JWT from the dashboard. If it works, the old key material was the problem; find every place it was cached.

When to use

You hit exactly this: Supabase PGRST301 JWT invalid: the anon key and service role key are not interchangeable in Supabase PGRST301 JWT invalid.

When not to use

A different error, or the same symptom in a different tool. This page only covers the failure above.

Compatibility

Supabase PGRST301 JWT invalid.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Supabase+PGRST301+JWT+invalid%3A+the+anon+key+and+service+role+key+are+not+interchangeable&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.